
the-art-of-pivoting
The Art of Pivoting - Techniques for Intelligence Analysts to Discover New Relationships in a Complex World

The Art of Pivoting - Techniques for Intelligence Analysts to Discover New Relationships in a Complex World

Detection of malicious VHD files for CVE-2025-24985

Incident Response Documentation made easy. Developed by Incident Responders for Incident Responders

Universal Windows extraction tool that detects unknown files and routes them to the right bundled extractor.

A bare-metal x86 utility to dump physical RAM directly to disk. Built and tested for Cold Boot Attack experiments on frozen memory.

Volatility 3 ported to Rust. Same output, much faster.

Abuses macOS debugger entitlements and DYLD_INSERT_LIBRARIES to dump or search a running process's memory while shifting EDR attribution to a signed…

PowerShell script to scan Windows Event Logs for CVE-2020-1472 indicators (events 5827-5831), export to CSV, and generate Excel pivot tables for…

Extract all forensic interesting information of Firefox, Iceweasel and Seamonkey browsers

Repository created to share information about tactics, techniques and procedures used by threat actors. Initially with ransomware groups and evolving…

Repository created to share information about tactics, techniques and procedures used by threat actors. Initially with ransomware groups and evolving…

macOS forensic timeline generator using the analysis result DBs of mac_apt

This framework combines a set of existing open source tools into an integrated package that automates the forensics investigation process. It is able…

We are presented with a security alert indicating the detection of the Follina (CVE-2022-30190) vulnerability. A malicious Word document triggered…

USB device connection forensics tool that traces physical device-to-computer relationships across local and domain networks, generating visual graphs…

Extracts and decrypts the 4-digit restriction passcode from iPhone backups on Windows machines, enabling recovery of device access controls.

Full analysis of a never documented before Remote Access Trojan linked to Pjoao1578 toolchain

A lightweight CLI tool to detect and reconstruct cropped images vulnerable to Acropalypse (CVE-2023-21036 and CVE-2023-28303) written in Python.